CVE-2026-16262
Estatik < 4.3.3 - Login CSRF
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and readable by the attacker.
| Vendor | unknown |
| Product | estatik real estate plugin |
| Published | Aug 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown estatik real estate plugin
Be the first to know when new unknown vulnerabilities affecting unknown estatik real estate plugin are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Estatik Real Estate Plugin
0 < 4.3.3
References
Credits
Yaswanth Reddy Sunkara WPScan